Subpart F Check

Answer a few questions about your facility and we will tell you which parts of the Coast Guard’s cybersecurity rule apply to it, with the section and the deadline for each, and which ones are already past due.

We ask nothing about your systems or what a scan found, and send nothing unless you use the form at the end.

Start

Ten questions, about two minutes.

Or read the full set of Subpart F requirements, with the section and deadline for each.

How this works

Who is asking, and why. Breakwater Cyber Corp sells one thing: we supply the named Cybersecurity Officer a regulated facility must designate under 33 CFR 101.625, and we do the compliance work the rule assigns to that role. This Check is free and is not conditional on buying anything. We built it because a facility that knows which obligations attach to it is a facility that can decide what to do about them, including doing it themselves. You can reach us at contact [at] breakwatercybercorp [dot] com.

If a letter brought you here. We wrote to a number of facility operators about this rule. The letter pointed at this site rather than at this page, so if you arrived from it, this is the Check it referred to.

What we do not ask. Nothing about your systems, your configuration, your network, your vulnerabilities or anything that failed a scan. Every question below asks whether a requirement is met, not how anything works. We do not want that information at this stage, and we have not built anywhere to put it.

It runs entirely in your browser. Your answers are not sent to us unless you choose to send them at the end, and you can confirm that in your browser’s network tab.

We count visits with Google Analytics, and your answers are not part of it. Like most sites we measure how many people arrive and how far they get, using Google Tag Manager and Google Analytics. That records pages and events, not the answers you give below: nothing you enter in the Check is sent anywhere unless you use the form at the end. You can confirm that in your browser’s network tab.

The Check

The questions

Answer these against your own facility. Below them is the full set of Subpart F requirements.

1. Is this facility, vessel or OCS facility required to have a security plan under 33 CFR Part 104, 105 or 106? An approved Alternative Security Program counts as yes.
2. Which is it?
3. How many facilities does your organisation operate?
4. Has a Cybersecurity Officer been designated in writing?
5. The rule requires the Cybersecurity Officer to be accessible to the Coast Guard 24 hours a day, 7 days a week โ€” ยง101.620(b)(3). Is that arrangement in place?
6. Have you decided how you will meet these requirements?
7. Has cybersecurity training been delivered to personnel with security duties?
8. Has a Cybersecurity Assessment been completed?
9. Where is your Cybersecurity Plan?
10. Has it been decided who will perform the annual audit of the Plan?
Reference

What 33 CFR 101 Subpart F requires

Subpart F applies to the owners and operators of U.S.-flagged vessels, facilities and OCS facilities required to have a security plan under 33 CFR Parts 104, 105 and 106 (ยง101.605(a)). That includes facilities operating under an approved Alternative Security Program under ยง105.140.

  • Cybersecurity training for all personnel with access to IT or OT systems, including contractors, and additional training for key personnel. ยง101.650(d) โ€” from 12 January 2026, and annually thereafter (ยง101.650(d)(4))
  • A Cybersecurity Assessment addressing each covered vessel, facility and OCS facility. ยง101.650(e)(1) โ€” no later than 16 July 2027, and annually thereafter
  • A Cybersecurity Plan containing the fourteen sections the rule lists. ยง101.630(c)
  • Submission of the Cybersecurity Plan to the Coast Guard for review and approval. ยง101.655 โ€” no later than 16 July 2027
  • Designate a Cybersecurity Officer in writing, by name and by title, accessible to the Coast Guard 24 hours a day, 7 days a week, and identify how they can be contacted at any time. ยง101.620(b)(3)
  • The Cybersecurity Officer carries the fifteen duties the rule attaches to the role. ยง101.625(d)
  • The Cybersecurity Officer must have general knowledge, through training, education or equivalent job experience, in the twelve areas the rule lists. ยง101.625(e)
  • A Cyber Incident Response Plan, developed, approved, executed and exercised. ยง101.620(b)(6) ยท ยง101.625(d)(4)
  • Reportable cyber incidents recorded and reported to the owner or operator, and reported by the owner or operator to the National Response Center. ยง101.625(d)(10) ยท ยง101.620(b)(7)
  • Records created and maintained for training, drills, exercises, cybersecurity threats, reportable cyber incidents and audits of the Plan. ยง101.640
  • Cybersecurity drills at least twice each calendar year. ยง101.635(b)(1)
  • A cybersecurity exercise at least once each calendar year, with no more than 18 months between exercises, including the substantial and active participation of the Cybersecurity Officer. ยง101.635(c)(1), (c)(5)
  • An annual audit of the Plan and its implementation. Personnel conducting it must not have regularly assigned cybersecurity duties for the facility being audited, and must be independent of the measures audited. §101.630(f)(1) assigns this one to the Cybersecurity Officer by name rather than to the owner or operator: the CySO must ensure the audit is performed, and the CySO must attach a report to the Plan certifying that the Plan meets the applicable requirements of this subpart. ยง101.630(f)(1), (f)(4)
  • A penetration test in conjunction with Cybersecurity Plan renewal. ยง101.650(e)(2)

This reports what the rule says. It is not legal advice and it is not a determination of whether the rule applies to your facility โ€” that is the Coast Guard's. Reflects the rule as at 10 August 2026.

Next step

What to do with this

If you are unsure whether the rule reaches your facility, your Sector office is the right place to confirm.

Three of these are harder than they look. The officer has to be reachable by the Coast Guard at any hour of any day, and the annual audit cannot be done by whoever runs the programme. The rule also requires that person to hold general knowledge across twelve areas §101.625(e) — facility operations, the facility’s own Cyber Incident Response Plan, conducting audits and inspections, handling Sensitive Security Information, and current threat patterns and known exploited vulnerabilities among them.

If you would like it in writing, we will send it. If you would like to talk about who does the work, book a call.

Schedule a call